Skip to content
US-INFEDERAL profile2 enforcement actions

Indiana — Consumer Data Protection Act (IC 24-15; in force 1 Jan 2026 — profiling opt-out + DPIAs) + State AI Laws (HEA 1133 election fabricated media; HEA 1047 AI intimate images; HEA 1271 insurer/provider AI claim review; SEA 256 AI-vendor state contracts) + Federal AI Profile: AI Compliance Requirements

Indiana has no single horizontal "AI act," but as of August 2026 it regulates automated decision-making through a LIVE comprehensive privacy statute plus four narrower AI-specific laws. (1) The INDIANA CONSUMER DATA PROTECTION ACT (SEA 5, 2023; IC 24-15) took effect 1 JANUARY 2026 and is now in force. It applies to a person conducting business in Indiana that in a calendar year controls or processes personal data of at least 100,000 Indiana consumers, or at least 25,000 Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data (IC 24-15-1-1), with entity-level exemptions for GLBA financial institutions, HIPAA covered entities, nonprofits, higher-education institutions and public utilities. Its AI surface is direct: consumers may opt out of "profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer" (IC 24-15-3-1(b)), where "profiling" means "any form of solely automated processing" used to evaluate, analyze or predict personal aspects such as economic situation, health, preferences, reliability, behavior, location or movements (IC 24-15-2-23); controllers must run documented data protection impact assessments before profiling that carries a reasonably foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial/physical/reputational injury, offensive intrusion, or other substantial injury (IC 24-15-6-1); and sensitive data — including biometric data processed to uniquely identify an individual — may not be processed without consent (IC 24-15-4-1, IC 24-15-2-28). Enforcement is EXCLUSIVELY the Attorney General's (IC 24-15-10-1) — there is NO private right of action — with injunctive relief and civil penalties up to $7,500 per violation plus the AG's investigation expenses and attorney's fees (IC 24-15-10-2), and only after a 30-day written notice to cure (IC 24-15-10-3), a cure right the statute does not sunset. (2) HEA 1133 / P.L. 81-2024 (effective July 1, 2024) requires election campaign communications containing "fabricated media" depicting a candidate to carry the disclaimer "Elements of this media have been digitally altered or artificially generated" (IC 3-9-8-5), and lets the depicted candidate sue for actual damages, injunctive relief, court costs and reasonable attorney's fees (IC 3-9-8-6). (3) HEA 1047 (2024) amended IC 35-45-4-8 so that a criminal "intimate image" includes one "created or modified by means of a computer software program, artificial intelligence, application, or other digital editing tools" — non-consensual distribution is a Class A misdemeanor, a Level 6 felony on a prior unrelated conviction. (4) HEA 1271 / P.L. 88-2026 adds IC 27-1-52 (effective July 1, 2026, now live): an insurer may not use an automated process, system or tool "including artificial intelligence" as the sole basis to downcode a claim on medical-necessity grounds without an employee or contractor reviewing the medical record; a PROVIDER may likewise not use such a tool to submit a claim without human review; and an insurer must disclose "in an easily accessible and readable manner" when AI is used to make an adverse prior-authorization determination or to downcode a claim (IC 27-1-52-9). "Insurer" expressly reaches a third-party contractor of an insurer, HMO or dental PPO (IC 27-1-52-6(4)), so AI and utilization-review vendors are in scope; Medicaid and Medicaid MCOs are excluded (IC 27-1-52-0.3). (5) SEA 256 / P.L. 131-2026 adds IC 1-1-15.3 (effective July 1, 2026): contracts by the state, a state agency or a political subdivision for a "technological product or service" — defined to include artificial intelligence (IC 1-1-15.3-6) — must require the contractor to confirm that it and its subcontractors are not foreign-adversary-linked "prohibited persons," with breach treated as a material breach of contract. Separately, breach notification runs on a hard clock: notice without unreasonable delay and not more than 45 days after discovery (IC 24-4.9-3-3), AG-enforced with civil penalties up to $150,000 per deceptive act (IC 24-4.9-4-2). SEA 150 (2024, AI & cybersecurity task force) and HEA 1108 (2024, state AI inventory) remain GOVERNMENT-ONLY and impose no private duty. Verify-the-negative (all re-checked 2026-08-25): Indiana has NO AI-chatbot statute and does not appear in the Future of Privacy Forum 2026 chatbot tracker; NO BIPA-style biometric statute; Indiana is NOT an adopter of the NAIC Model Bulletin on the Use of AI Systems by Insurers per the NAIC implementation map "Status as of April 1, 2026" — its insurance-AI duty is statutory (IC 27-1-52) instead; HB 1620 (healthcare-AI disclosure) and HB 1182 (AI NCII) are NOT enacted. Indiana is a major auto manufacturing hub (Subaru of Indiana, Stellantis, Toyota) and pharmaceutical center (Eli Lilly, Roche Diagnostics, Cook Medical). Federal laws apply: FTC Act § 5, Title VII / ADA (employment — critical for manufacturing AI monitoring), FCRA (lending), COPPA (children's data), and FDA Software as a Medical Device guidance for healthcare and pharmaceutical AI.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2024

Maximum Penalty

Indiana Consumer Data Protection Act (IC 24-15, in force since 1 Jan 2026): injunctive relief plus a civil penalty of up to $7,500 for EACH violation, and recovery of the Attorney General's reasonable investigation expenses and attorney's fees (IC 24-15-10-2) — AG-exclusive (IC 24-15-10-1), no private right of action, and only after 30 days' written notice to cure (IC 24-15-10-3). Data-breach notification: up to $150,000 per deceptive act (IC 24-4.9-4-2). Deceptive Consumer Sales Act: up to $5,000 per violation, and up to $15,000 per violation of an injunction (IC 24-5-0.5-4). AI intimate images (IC 35-45-4-8, as amended by HEA 1047): Class A misdemeanor — up to 1 year and a fine up to $5,000 (IC 35-50-3-2); Level 6 felony on a prior unrelated conviction — 6 months to 2.5 years and a fine up to $10,000 (IC 35-50-2-7). Election fabricated media (IC 3-9-8-6): private candidate suit for actual damages, injunction, costs and attorney's fees — no statutory cap. Insurer/provider AI claim review (IC 27-1-52): no civil-penalty section in the chapter; Department of Insurance rulemaking under IC 4-22-2. Federal FTC civil penalties up to $53,088 per violation.

What Your Business Must Do

13 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Indiana Election "Fabricated Media" AI Disclaimer — HEA 1133 / P.L. 81-2024 (IC 3-9-8)

High Priority

HEA 1133 / Public Law 81-2024 (effective July 1, 2024) adds IC 3-9-8 ("Use of Digitally Altered Media in Elections"). IC 3-9-8-5 requires a campaign communication that includes "fabricated media depicting a candidate" to carry the disclaimer "Elements of this media have been digitally altered or artificially generated," with the disclaimer prescribed separately for printed, audio and video formats. IC 3-9-8-6 gives the remedy to the depicted candidate, not to a state agency: "A candidate depicted in fabricated media that is included in a campaign communication that does not include a disclaimer required by section 5 of this chapter may bring a civil action," recovering "the plaintiff's actual damages," "injunctive relief," and "the amount of any court costs and reasonable attorney's fees." Practical consequence for any Indiana political-media, agency or platform workflow: generative-AI depictions of a real candidate must be disclaimed at the point of distribution in every format, and the exposure is uncapped civil damages plus fee-shifting rather than a bounded regulatory fine. Statutory text verified 2026-08-25 against the Indiana Code mirror at codes.findlaw.com, stamped "Current as of January 01, 2026" (iga.in.gov serves only a JS shell to this toolchain). legal_review_pending.

Deadline: July 1, 2024

IC 3-9-8-5 (disclaimer text and formats) and IC 3-9-8-6 (candidate civil action and remedies), added by HEA 1133 / P.L. 81-2024; Indiana Code text "Current as of January 01, 2026"

Indiana Consumer Data Protection Act — Right to Opt Out of Profiling in Automated Decisions (IC 24-15-3-1)

High Priority

The Indiana Consumer Data Protection Act (SEA 5, 2023; IC 24-15) has been IN FORCE since 1 January 2026. IC 24-15-3-1(b) gives an Indiana consumer the right to confirm and access, correct, delete, obtain a portable copy or representative summary, and "opt out of the processing of the consumer's personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer." "Profiling" is defined at IC 24-15-2-23 as "any form of solely automated processing" performed on personal data to evaluate, analyze or predict personal aspects relating to an identified or identifiable individual's economic situation, health or health records, personal preferences, interests, reliability, behavior, location or movements — so the opt-out reaches AI scoring, ranking, eligibility and targeting models applied to Indiana residents, and the "solely automated" qualifier means a genuine, documented human decision step takes a process outside the definition. A controller must respond within 45 days, extendable once by a further 45 days, free of charge up to once annually per consumer, and must offer an internal appeal process for refusals. Note the Indiana-specific narrowing: "sale of personal data" means exchange for MONETARY consideration (IC 24-15-2 definitions), which is narrower than the "other valuable consideration" formulations in several sister states — do not assume a California/Colorado analysis transfers. Statutory text verified 2026-08-25 against the Indiana Code mirror at codes.findlaw.com, stamped "Current as of January 01, 2026". legal_review_pending.

Deadline: January 1, 2026

IC 24-15-3-1(b) (consumer rights incl. profiling opt-out; 45-day response, one 45-day extension, right to appeal); IC 24-15-2-23 ("profiling" = "any form of solely automated processing"); IC 24-15-1-1 (applicability thresholds); IC 24-15-10-1 to 24-15-10-3 (enforcement); Indiana Code text "Current as of January 01, 2026"

Indiana Consumer Data Protection Act — Data Protection Impact Assessments for Risk-Bearing Profiling (IC 24-15-6-1)

High Priority

IC 24-15-6-1 requires a controller to conduct and document a data protection impact assessment before each of: processing personal data for targeted advertising; the sale of personal data; the processing of sensitive data; "any processing activities involving personal data that present a heightened risk of harm to consumers"; and — the AI-critical trigger — profiling that presents a reasonably foreseeable risk of "unfair or deceptive treatment of, or unlawful disparate impact on, consumers," of "financial, physical, or reputational injury to consumers," of "a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, if such intrusion would be offensive to a reasonable person," or of "other substantial injury to consumers." The assessment must identify and weigh the benefits of the processing against the risks to consumer rights, accounting for the use of de-identified data, reasonable consumer expectations, and the context of the processing. This is the operative disparate-impact testing obligation for AI models deployed against Indiana consumers, and it maps closely onto the EEOC adverse-impact analysis already required of employment tools — a single model-risk file can satisfy both if it is scoped to Indiana consumers as well as applicants. Timing carve-out to diary: the chapter "appl[ies] to processing activities created or generated after December 31, 2025, and [is] not retroactive to any processing activities created or generated before January 1, 2026," so legacy models escape only until they are materially changed or newly deployed. Verified 2026-08-25 against the Indiana Code mirror at codes.findlaw.com, "Current as of January 01, 2026". legal_review_pending.

Deadline: January 1, 2026

IC 24-15-6-1 (DPIA triggers, risk-weighing standard, and the post-December 31, 2025 non-retroactivity clause); enforcement via IC 24-15-10-1 to 24-15-10-3; Indiana Code text "Current as of January 01, 2026"

Indiana Consumer Data Protection Act — Consent for Sensitive and Biometric Data; Anti-Retaliation (IC 24-15-4-1)

High Priority

IC 24-15-4-1 imposes the controller duties that govern AI training and inference inputs: limit collection of personal data to what is "adequate, relevant, and reasonably necessary" for the disclosed purposes; do not process personal data for purposes incompatible with those disclosed without the consumer's consent (which squarely covers repurposing customer data as model training data); maintain reasonable administrative, technical and physical data security practices; and — the provision that carries the biometric duty — "A controller shall not process sensitive data concerning a consumer without obtaining the consumer's consent," with children's data handled under COPPA. "Sensitive data" (IC 24-15-2-28) includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis made by a health care provider, sexual orientation, or citizenship or immigration status, and "genetic or biometric data that is processed for the purpose of uniquely identifying a specific individual" — so face, voice, fingerprint, retina/iris and comparable biometric matching used by Indiana workforce, access-control or retail AI needs prior consent. IC 24-15-4-1 also bars discriminating against a consumer for exercising a right, including denying goods or services or charging a different price in retaliation, while permitting genuine loyalty-program and opt-out-driven differences. VERIFY-THE-NEGATIVE: Indiana has NO standalone BIPA-style biometric statute and no biometric private right of action — this consent duty, AG-enforced, is the whole of Indiana biometric law. Verified 2026-08-25 against the Indiana Code mirror at codes.findlaw.com, "Current as of January 01, 2026". legal_review_pending.

Deadline: January 1, 2026

IC 24-15-4-1 (data minimization, purpose limitation, security, non-discrimination, sensitive-data consent); IC 24-15-2-28 ("sensitive data", including biometric data processed to uniquely identify an individual); enforcement IC 24-15-10-1 to 24-15-10-3; Indiana Code text "Current as of January 01, 2026"

Health Insurer AND Provider AI Claim Review — HEA 1271 / P.L. 88-2026 (IC 27-1-52), live since 1 July 2026

High Priority

HEA 1271 adds a new chapter IC 27-1-52 ("Downcoding of Health Benefits Claims"), effective July 1, 2026 and now live. IC 27-1-52-9 states the AI rules in three parts. (a) An insurer "may not use an automated: (1) process; (2) system; or (3) tool, including artificial intelligence; as the sole basis to downcode a claim based on medical necessity without the review of the covered individual's medical record by an employee or contractor of the insurer." (b) The SAME prohibition runs the other way — "A provider may not use an automated ... tool, including artificial intelligence; to submit a health benefits claim without the review of a provider or other person involved in the development of the claim for submission" — so revenue-cycle and autonomous-coding AI on the provider side is regulated too, a duty missing from earlier versions of this entry. (c) "An insurer must disclose in an easily accessible and readable manner when artificial intelligence is used to: (1) make an adverse determination on a prior authorization request; or (2) downcode a claim." Scope traps that decide applicability: "insurer" expressly includes "a third party contractor" of an insurer, HMO or dental preferred-provider plan (IC 27-1-52-6(4)), so AI vendors and delegated utilization-review firms are directly bound rather than merely contractually flowed-down; and the chapter "does not apply to the Medicaid program or a managed care organization ... that provides services to a Medicaid recipient" (IC 27-1-52-0.3). Surrounding duties in the same chapter shape the audit trail an AI pipeline must emit: downcoding notice via the appropriate CARC and RARC with the specific clinical criteria relied on (IC 27-1-52-11), an appeal window of not less than 180 days with batch appeals for substantially similar issues (IC 27-1-52-12), no downcoding based solely on the reported diagnosis code (IC 27-1-52-10), and no targeted or discriminatory downcoding against providers who routinely treat complex or chronic conditions (IC 27-1-52-13) — an anti-disparate-impact rule aimed squarely at model behaviour. Text verified 2026-08-25 by reading the enrolled act PDF itself via an S3 mirror of the IGA document (iga.in.gov serves this toolchain a JS shell). legal_review_pending.

Deadline: July 1, 2026

IC 27-1-52-9(a)-(c) (AI/automated-tool prohibitions and disclosure), IC 27-1-52-6(4) ("insurer" includes a third party contractor), IC 27-1-52-0.3 (Medicaid exclusion), IC 27-1-52-10, -11, -12, -13 (diagnosis-code bar, CARC/RARC notice, 180-day appeals, non-discriminatory downcoding), IC 27-1-52-14 (department rulemaking under IC 4-22-2), added by HEA 1271 / P.L. 88-2026

Indiana Data-Breach Notification — 45-Day Clock (IC 24-4.9)

High Priority

Indiana runs one of the tighter state breach clocks and it governs AI incidents (model or vendor compromise, prompt/log exfiltration, training-corpus exposure) exactly as it governs any other system: "A person required to make a disclosure or notification under this chapter shall make the disclosure or notification without unreasonable delay, but not more than forty-five (45) days after the discovery of the breach" (IC 24-4.9-3-3). Delay is permitted only in response to a request from the Attorney General or a law enforcement agency. Because the 45 days run from DISCOVERY rather than from confirmation or completion of a forensic investigation, an AI vendor contract that lets a processor sit on an incident while it investigates will breach the Indiana clock; flow-down notice obligations should be set materially shorter than 45 days. The Attorney General enforces, and unlike the INCDPA this chapter carries a six-figure ceiling. Statutory text verified 2026-08-25 against the Indiana Code mirror at codes.findlaw.com, "Current as of January 01, 2026". legal_review_pending.

Deadline: January 1, 2026

IC 24-4.9-3-3 (45-day outer limit from discovery; AG/law-enforcement delay); IC 24-4.9-4-2 (AG enforcement and civil penalty); Indiana Code text "Current as of January 01, 2026"

FTC Act § 5 — Deceptive or Unfair AI Practices

High Priority

FTC Act § 5 applies to all Indiana businesses using AI. Ensure AI-generated product claims are truthful, AI chatbots disclose their nature, and AI-driven pricing and marketing practices are not unfair or deceptive. Indiana consumer protection law (Ind. Code § 24-5-0.5) may apply independently to deceptive AI claims.

15 U.S.C. § 45(a) (unfair/deceptive practices); civil-penalty authority § 45(l), § 45(m)(1)(A), 16 CFR 1.98; Ind. Code § 24-5-0.5-4 (Deceptive Consumer Sales Act penalties and consumer action); Indiana Code text "Current as of January 01, 2026"

EEOC / Title VII / ADA — AI Employment Screening in Manufacturing

High Priority

Indiana's large manufacturing sector (Subaru, Stellantis, Toyota) and logistics companies increasingly use AI for worker monitoring, scheduling, and safety alerts. EEOC May 2023 technical assistance requires employers to test AI employment tools for disparate impact on race, sex, age, and disability. Manufacturing AI vendors must provide disparate impact documentation. Ensure AI worker surveillance does not have discriminatory scheduling or performance effects.

Title VII, 42 U.S.C. § 2000e-2; ADA, 42 U.S.C. § 12112; damages caps at 42 U.S.C. § 1981a(b)(3)

AI-Generated or AI-Altered Intimate Images — HEA 1047 (2024), IC 35-45-4-8

Medium Priority

HEA 1047 (2024, effective July 1, 2024) amended Indiana's non-consensual intimate image offence so that an "intimate image" expressly includes a photograph, digital image, computer-generated image or video "created or modified by means of a computer software program, artificial intelligence, application, or other digital editing tools" (IC 35-45-4-8). Distribution of such an image without the depicted person's consent is a criminal offence prosecuted by county and district attorneys, with statutory exceptions for criminal investigations, mandated reports, court orders and news reporting. This is a private-binding AI law and it is the reason the frequently repeated claim that "Indiana has only two AI laws" is wrong; it also means an Indiana-facing generative image or video product needs consent, provenance and takedown controls at the distribution layer, not merely at the model layer. Distinguish it from the separate bill HB 1182 (AI NCII), which was NOT enacted and must not be cited as law. Statutory text verified 2026-08-25 against the Indiana Code mirror at codes.findlaw.com, "Current as of January 01, 2026"; sentencing ranges verified against IC 35-50-3-2 and IC 35-50-2-7 in the same mirror. legal_review_pending.

Deadline: July 1, 2024

IC 35-45-4-8 (distribution of an intimate image; definition covering images created or modified by artificial intelligence), as amended by HEA 1047 (2024); sentencing at IC 35-50-3-2 (Class A misdemeanor) and IC 35-50-2-7 (Level 6 felony)

AI Vendors Contracting with Indiana Government — SEA 256 / P.L. 131-2026 (IC 1-1-15.3)

Medium Priority

SEA 256 adds a new chapter IC 1-1-15.3, "Prohibition on Technology Contracts with Certain Foreign Owned Companies," effective July 1, 2026. IC 1-1-15.3-6 defines a "technological product or service" as "a product or service used for information systems, surveillance, light detection and ranging, or artificial intelligence" (excluding unmanned aerial systems), which places AI products squarely inside the chapter. IC 1-1-15.3-7 provides that after June 30, 2026 for a NEW contract, and after June 30, 2027 for an EXISTING contract that is amended or renewed, a contract by a "qualified entity" — the state, a state agency, or a political subdivision — for such a product or service "must contain a provision requiring the contractor to confirm that the contractor and any subcontractors working under the contract for the contractor are not prohibited persons," and "A breach of the provisions under this section may be regarded as a material breach of the contract." "Prohibited person" (IC 1-1-15.3-4) reaches entities organized or headquartered in a foreign adversary — the People's Republic of China, the Russian Federation, North Korea, Iran, a foreign government listed in 15 CFR 791.4, or a country the governor designates a critical-infrastructure threat under IC 1-1-16-8 — or having a controlling person (51% beneficial owner, officer/director with inside information, or a person able to affect management or policies) who is a citizen of or domiciled in a foreign adversary, with carve-outs for US citizens, lawful permanent residents, dual citizens and asylees. Practical effect for an AI vendor: model-supply-chain and subcontractor ownership diligence becomes a contract-formation prerequisite for Indiana public-sector sales, and a stale answer is a material breach rather than a mere representation. Text verified 2026-08-25 by reading SENATE ENROLLED ACT No. 256 itself via an S3 mirror of the IGA enrolled PDF. legal_review_pending.

Deadline: July 1, 2026

IC 1-1-15.3-6 ("technological product or service" includes artificial intelligence), IC 1-1-15.3-7 (mandatory contractor/subcontractor confirmation; material breach; 30 June 2026 new-contract and 30 June 2027 renewal dates), IC 1-1-15.3-4 ("prohibited person"), IC 1-1-15.3-3 ("foreign adversary"), IC 1-1-15.3-5 ("qualified entity"), added by SEA 256 / P.L. 131-2026

FCRA / CFPB — AI Credit and Lending Compliance

Medium Priority

Indiana's financial services sector and fintech companies using AI credit scoring must comply with FCRA adverse action notice requirements. CFPB Circular 2022-03 requires specific adverse action reasons from the consumer's file — not generic model outputs. Auto lenders financing Indiana vehicle manufacturing output (Toyota, Stellantis) also face FCRA obligations for AI-assisted financing decisions.

15 U.S.C. § 1681b(b)(3) (adverse action notice); §§ 1681n, 1681o (civil liability); CFPB Circular 2022-03

FDA Software as a Medical Device (SaMD) — Healthcare AI

Medium Priority

Indiana is home to major pharmaceutical and medical device companies (Eli Lilly, Roche Diagnostics, Cook Medical). AI systems meeting the FDA's definition of Software as a Medical Device require FDA 510(k) clearance or De Novo authorization. AI diagnostic tools, clinical decision support, and drug discovery AI must comply with FDA's 2021 AI/ML-Based SaMD Action Plan and 2023 marketing submission guidance.

21 U.S.C. § 360c et seq. (FDCA medical device provisions); 21 U.S.C. § 360j(o) (SaMD); civil-penalty authority 21 U.S.C. § 333(f)(1)(A)

Monitor Indiana AI Legislation — and How to Monitor It Without Being Misled

Lower Priority

Monitor the Indiana General Assembly for private-sector AI legislation, but do NOT monitor by bill title. Demonstrated 2026-08-25: the Governor's own signed-legislation repository for the 2026 session lists roughly 180+ enacted bills and NOT ONE description mentions artificial intelligence, deepfakes, algorithms or privacy — yet two of those bills contain Indiana's newest AI obligations, HEA 1271 (listed as "Payment of health claims", carrying IC 27-1-52-9's AI prohibitions) and SEA 256 (a "state offices and administration" act, carrying IC 1-1-15.3's AI-vendor contract rule). A title scan or an AI-keyword bill-tracker count would have scored Indiana at zero AI enactments for 2026. Only enrolled text settles the question, so review enrolled acts in the insurance, elections, criminal-law, procurement and health-services subject areas each session. Two further monitoring notes carrying negative findings as of this date: Indiana has enacted NO AI-chatbot statute and does not appear in the Future of Privacy Forum 2026 chatbot-legislation tracker (fifteen states do), and Indiana has NOT adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers — it is uncoloured on the NAIC Big Data & AI (H) Working Group implementation map "Status as of April 1, 2026" and absent from that map's 25-jurisdiction reference list — so watch for a statutory instrument like IC 27-1-52 rather than for an insurance bulletin. Also diary Department of Insurance rulemaking under IC 27-1-52-14, which will supply the enforcement detail the statute omits. Tooling note for whoever next verifies this entry: iga.in.gov serves this toolchain a bare JS shell for HTML pages and for its own static Code and bill PDFs, and events.in.gov (AG press releases) returns HTTP 403; use the codes.findlaw.com Indiana Code mirror (carries a "Current as of" stamp) and the billtexts S3 mirror of IGA enrolled-act PDFs.

Recent Enforcement Actions

2024-04-15Source verified· as of 2026-08-25

Against:

Indiana Attorney General (Todd Rokita)2022-12-29Source verified· as of 2026-08-25

Against: Google LLC

Recent Regulatory Guidance

guidance2026-01-01

Indiana Attorney General: Indiana Consumer Data Protection Act — Consumer Data Bill of Rights

Guidance booklet issued by Indiana Attorney General Todd Rokita and prepared by his office's Data Privacy & Identity Theft Unit, setting out how the office reads the INCDPA and how it intends to enforce it. The AG states plainly that "Starting January 1, 2026, we will enforce Indiana's new Consumer Data Protection Act (CDPA)," frames the law against a "full-blown surveillance economy" in which "the information gathered about us is analyzed and even used to make decisions about us" — the profiling concern IC 24-15-3-1(b) addresses — and confirms the enforcement architecture: "This law also directs us — your Attorney General's Office — to enforce these important rights," with consumers directed to file complaints with the office rather than to sue. It also records the office's existing posture that it has "sued Google over their deceptive use of location data" and has enforced health-privacy rights under HIPAA. Useful as the regulator's own statement of intent for AI/profiling compliance narratives, and as evidence that Indiana enforcement runs through complaint intake plus the IC 24-15-10-3 cure notice.

guidance2023-05-18

EEOC: Assessing Adverse Impact in AI Employment Selection Tools (May 2023)

Technical assistance document explaining how to assess disparate impact in AI-driven employment screening tools — direct guidance for Indiana's manufacturing sector (Subaru, Stellantis, Toyota) using AI hiring, scheduling, and performance evaluation systems. Covers data collection, selection rate analysis, and employer liability for third-party AI vendor tools.

Frequently Asked Questions

Does Indiana — Consumer Data Protection Act (IC 24-15; in force 1 Jan 2026 — profiling opt-out + DPIAs) + State AI Laws (HEA 1133 election fabricated media; HEA 1047 AI intimate images; HEA 1271 insurer/provider AI claim review; SEA 256 AI-vendor state contracts) + Federal AI Profile apply to my business?

Indiana has no single horizontal "AI act," but as of August 2026 it regulates automated decision-making through a LIVE comprehensive privacy statute plus four narrower AI-specific laws. (1) The INDIANA CONSUMER DATA PROTECTION ACT (SEA 5, 2023; IC… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Indiana — Consumer Data Protection Act (IC 24-15; in force 1 Jan 2026 — profiling opt-out + DPIAs) + State AI Laws (HEA 1133 election fabricated media; HEA 1047 AI intimate images; HEA 1271 insurer/provider AI claim review; SEA 256 AI-vendor state contracts) + Federal AI Profile is: Indiana Consumer Data Protection Act (IC 24-15, in force since 1 Jan 2026): injunctive relief plus a civil penalty of up to $7,500 for EACH violation, and recovery of the Attorney General's reasonable investigation expenses and attorney's fees (IC 24-15-10-2) — AG-exclusive (IC 24-15-10-1), no private right of action, and only after 30 days' written notice to cure (IC 24-15-10-3). Data-breach notification: up to $150,000 per deceptive act (IC 24-4.9-4-2). Deceptive Consumer Sales Act: up to $5,000 per violation, and up to $15,000 per violation of an injunction (IC 24-5-0.5-4). AI intimate images (IC 35-45-4-8, as amended by HEA 1047): Class A misdemeanor — up to 1 year and a fine up to $5,000 (IC 35-50-3-2); Level 6 felony on a prior unrelated conviction — 6 months to 2.5 years and a fine up to $10,000 (IC 35-50-2-7). Election fabricated media (IC 3-9-8-6): private candidate suit for actual damages, injunction, costs and attorney's fees — no statutory cap. Insurer/provider AI claim review (IC 27-1-52): no civil-penalty section in the chapter; Department of Insurance rulemaking under IC 4-22-2. Federal FTC civil penalties up to $53,088 per violation.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Indiana — Consumer Data Protection Act (IC 24-15; in force 1 Jan 2026 — profiling opt-out + DPIAs) + State AI Laws (HEA 1133 election fabricated media; HEA 1047 AI intimate images; HEA 1271 insurer/provider AI claim review; SEA 256 AI-vendor state contracts) + Federal AI Profile?

The 13 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://in.gov/attorneygeneral

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan